Executive brief
Mailgen is a Node.js library that generates formatted email messages for transactional email services. The library contains a flaw in its plaintext email generation that fails to properly strip HTML and allow encoded HTML tags to be decoded later, enabling attackers to inject malicious HTML that could execute in the recipient's email client if rendered as HTML, potentially allowing credential theft or session hijacking.
Technical details
The vulnerability exists in the generatePlaintext() method, which is intended to strip HTML tags from email content. The flaw arises because the function performs regex-based HTML tag stripping before decoding HTML entities. An attacker can bypass this filter by embedding unicode line separator characters (such as U+2028) within HTML tags (e.g., <img src=x onerror=alert(1)⏎>), which prevents the regex from matching the malformed tag. After stripping fails, the subsequent he.decode() call converts the entities back to valid HTML. The vulnerability requires that user-generated content is passed directly to generatePlaintext(). The attack succeeds if the resulting plaintext email is later rendered as HTML (e.g., by an email client or message display system), allowing arbitrary JavaScript execution in the recipient's browser context.
Affected products
- Mailgen mailgen through 2.0.31
Timeline
- 2025-10-15: disclosed
- 2025-10-15: patched: Fixed in version 2.0.32